AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Triaging Incidents

skill-jschuller-mcp-server-servicenow-triaging-incidents · by jschuller

Creating, triaging, updating, and analyzing ServiceNow incidents. Assess severity, check affected CIs, find related incidents, and recommend assignments. Use when the user mentions incidents, INC numbers, outages, service disruptions, ticket creation, triage, priority, severity, ITSM operations, SLA breaches, assignment groups, \"what's on fire,\" or \"open P1 incidents.\

No reviews yet
0 installs
19 views
0.0% view→install

Install

$ agentstack add skill-jschuller-mcp-server-servicenow-triaging-incidents

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-jschuller-mcp-server-servicenow-triaging-incidents)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Triaging Incidents? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Triaging ServiceNow Incidents

Create, triage, investigate, and analyze incidents. See references/incident-fields.md for the priority matrix, states, categories, and encoded query patterns.

Workflows

1. List Recent Incidents

Get a summary of recent incidents by priority, state, or assignment group.

Progress checklist (copy into your response):

- [ ] Query incidents with filters
- [ ] Summarize by priority and state
- [ ] Highlight critical/P1 incidents
  1. List recent incidents (last 24 hours, open):

`` list_records(table_name="incident", query="active=true^sys_created_on>=javascript:gs.daysAgoStart(1)", fields="number,short_description,priority,state,assignment_group,assigned_to,sys_created_on", limit=20, order_by="-priority") ``

  1. For a specific assignment group:

`` list_records(table_name="incident", query="active=true^assignment_groupLIKE", fields="number,short_description,priority,state,assigned_to", limit=20) ``

  1. Summarize: total count, breakdown by priority (P1/P2/P3/P4), breakdown by state, highlight any P1/P2 incidents.

2. Triage a New Incident

Assess impact and urgency, then suggest priority, category, and assignment group.

Progress checklist:

- [ ] Get incident details
- [ ] Assess impact and urgency
- [ ] Check affected CI and its dependencies
- [ ] Suggest priority, category, assignment group
- [ ] Recommend next steps
  1. Get the incident details:

`` get_record(table_name="incident", sys_id="") ``

  1. If a CI is attached, check its relationships to assess blast radius:

`` get_ci(sys_id="") get_ci_relationships(sys_id="") ``

  1. Look for similar recent incidents (same CI or category):

`` list_records(table_name="incident", query="cmdb_ci=^sys_created_on>=javascript:gs.daysAgoStart(30)", fields="number,short_description,state,priority", limit=10) ``

  1. Recommend triage decisions:
  • Priority: Based on impact x urgency matrix (see references/incident-fields.md)
  • Category: Based on the affected CI class and description keywords
  • Assignment group: Based on CI ownership or category routing rules
  1. Present recommendations with reasoning.

3. Investigate an Incident

Deep-dive into an existing incident — full context, related CIs, similar incidents.

Progress checklist:

- [ ] Get full incident details
- [ ] Get affected CI details and relationships
- [ ] Find similar recent incidents
- [ ] Check for related problems or changes
- [ ] Summarize findings and recommend actions
  1. Get the full incident record:

`` get_record(table_name="incident", sys_id="") ``

  1. If a CI is attached, get its details and dependency chain:

`` get_ci(sys_id="") get_ci_relationships(sys_id="") ``

  1. Find similar recent incidents:

`` list_records(table_name="incident", query="categoryLIKE^sys_created_on>=javascript:gs.daysAgoStart(30)", fields="number,short_description,state,priority,resolution_notes", limit=10) ``

  1. Check for related problems:

`` list_records(table_name="problem", query="cmdb_ci=^active=true", fields="number,short_description,state", limit=5) ``

  1. Check for recent changes on the same CI:

`` list_records(table_name="change_request", query="cmdb_ci=^sys_created_on>=javascript:gs.daysAgoStart(7)", fields="number,short_description,state,type", limit=5) ``

  1. Summarize: incident context, CI dependency impact, related incidents/problems/changes, recommended actions.

4. Create an Incident

Create a new incident with validated fields and appropriate defaults.

Progress checklist:

- [ ] Validate required fields are provided
- [ ] Suggest category from description
- [ ] Set appropriate defaults (state, priority)
- [ ] Create the incident
- [ ] Confirm creation with INC number
  1. Validate required fields: short_description is mandatory. Confirm caller_id is provided.
  2. Suggest category based on description keywords (see references/incident-fields.md).
  3. Set defaults for missing fields:
  • state: 1 (New)
  • impact: 3 (Low) unless specified
  • urgency: 3 (Low) unless specified
  • priority is auto-calculated from impact x urgency
  1. Create the incident:

`` create_record(table_name="incident", data={"short_description": "...", "description": "...", "caller_id": "...", "category": "...", "impact": "3", "urgency": "3", "cmdb_ci": "..."}) ``

  1. Confirm creation: return the INC number, priority, and link.

5. Bulk Analysis

Analyze incident trends — top categories, repeat offenders, SLA status.

Progress checklist:

- [ ] Pull recent incidents (7-30 day window)
- [ ] Group by category
- [ ] Identify repeat CIs (frequent flyers)
- [ ] Check SLA breaches
- [ ] Present trends and recommendations
  1. Pull recent incidents:

`` list_records(table_name="incident", query="sys_created_on>=javascript:gs.daysAgoStart(30)^active=true", fields="number,category,cmdb_ci,priority,state,assignment_group,sla_due", limit=100, order_by="-sys_created_on") ``

  1. Group by category — which categories generate the most incidents?
  2. Identify repeat CIs — which CIs appear in multiple incidents?

`` list_records(table_name="incident", query="cmdb_ci=^sys_created_on>=javascript:gs.daysAgoStart(30)", fields="number,short_description,priority,state", limit=20) ``

  1. Check for SLA breaches:

`` list_records(table_name="incident", query="active=true^sla_due", fields="name,sys_id").

  • See references/incident-fields.md for encoded query patterns and field reference.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.